Monitoring Azure Environment

Denny Ahn 0 Reputation points
2026-03-05T00:08:45.3133333+00:00

A subscription-level attack occurred in mid-December 2025, creating 231 VMs. Microsoft sent me an invoice a month later, which made me aware of the issue. It took nearly two months to investigate and resolve the issue.

I have configured a policy to restrict Azure VM creation. I'd like to monitor at the Subscription level, as attacks can come from other sources, not just the VM.

I want to prevent this from happening in the future. I want to configure Azure to alert me when activity is abnormal and protect my environment.

Thank you.

Microsoft Security | Microsoft Entra | Other
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.